ICS/OT Vulnerability Index

New flaws in your industrial hardware

Industry 4.0 connects machines – and widens the attack surface. This radar counts new security advisories (ICS-CERT) for the automation vendors that run German factories: Siemens, Phoenix Contact, WAGO, Beckhoff, SICK, Schneider, Rockwell, ABB and more.

As of 30 September 2026
2,036advisories in total (since 2010)
263new in the last 12 months
446critical in total
9affected German vendors
Latest critical advisory22 Sept 2026

Siemens Siveillance Control

CVSS 9.0SiemensDECVE-2026-50093View CISA advisory

By severity

Distribution of all tracked advisories by CVSS severity.

Critical · 446High · 1,092Medium · 461Low · 32n/a · 5

Advisories per month

New advisories per month for the tracked vendors – rolling window; the red peak marks the busiest month.

By vendor

Which automation vendors account for the most advisories. “DE” = headquartered in Germany.

  1. SiemensDE1,061
  2. Rockwell Automation274
  3. Schneider Electric255
  4. Mitsubishi Electric142
  5. Hitachi Energy112
  6. ABB96
  7. Omron30
  8. Phoenix ContactDE25
  9. FestoDE15
  10. WAGODE13
  11. Pepperl+FuchsDE6
  12. BeckhoffDE4
  13. SICKDE1
  14. PilzDE1
  15. TurckDE1

More advisories doesn't mean “less secure” – large, widely deployed portfolios (e.g. Siemens) simply generate more reports.

Recent advisories

The latest ICS-CERT advisories for the tracked vendors.

  1. CriticalCVSS 9.0Siemens22 Sept 2026

    Siemens Siveillance Control

    Critical Manufacturing; Communications; Commercial FacilitiesCVE-2026-50093View CISA advisory
  2. HighCVSS 7.8Siemens22 Sept 2026

    Siemens SIPLUS and SIMATIC Products

    Critical Manufacturing; Energy; Water and Wastewater Systems; Chemical; Food and Agriculture; Commercial FacilitiesCVE-2026-31431View CISA advisory
  3. HighCVSS 8.2Siemens22 Sept 2026

    Siemens Desigo CC family

    Critical Manufacturing; Commercial FacilitiesCVE-2026-34223View CISA advisory
  4. CriticalCVSS 9.1Siemens22 Sept 2026

    Siemens Industrial Edge Management

    Critical ManufacturingCVE-2026-18963View CISA advisory
  5. HighCVSS 8.6Siemens22 Sept 2026

    Siemens SIMOVE Fleetmanager and SIPLANT

    Critical ManufacturingCVE-2026-67367View CISA advisory
  6. MediumCVSS 6.5Siemens22 Sept 2026

    Siemens WTV676 and WTV776

    EnergyCVE-2026-89207View CISA advisory
  7. HighCVSS 8.8Mitsubishi Electric17 Sept 2026

    Mitsubishi Electric GX Works3 and Motion Control Settings

    Critical ManufacturingCVE-2026-15688View CISA advisory
  8. CriticalCVSS 9.9Hitachi Energy17 Sept 2026

    Hitachi Energy FACTS Control Platform (FCP)

    EnergyCVE-2024-4872 +4View CISA advisory
  9. HighCVSS 7.5Schneider Electric17 Sept 2026

    Schneider Electric Modicon M340 Controller and Communication Modules

    Chemical; Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater SystemsCVE-2025-6625View CISA advisory
  10. MediumCVSS 6.4Schneider Electric17 Sept 2026

    Schneider Electric NetBotz 5 750/755

    Commercial Facilities; Critical Manufacturing; Information TechnologyCVE-2026-13336 +1View CISA advisory
  11. HighCVSS 7.8ABB17 Sept 2026

    ABB Ability Edgenius

    Critical Manufacturing; Energy; Water and Wastewater Systems; ChemicalCVE-2026-31431View CISA advisory
  12. MediumCVSS 5.3Schneider Electric17 Sept 2026

    Schneider Electric PowerChute Serial Shutdown

    Commercial Facilities; Critical Manufacturing; Energy; Information TechnologyCVE-2026-13348View CISA advisory
  13. MediumCVSS 6.5Schneider Electric15 Sept 2026

    Schneider Electric SCADAPack x70 Products

    Critical Manufacturing; EnergyCVE-2026-81861View CISA advisory
  14. CriticalCVSS 9.8Siemens15 Sept 2026

    Siemens Reyrolle 7SR5

    EnergyCVE-2024-42384 +13View CISA advisory
  15. HighCVSS 8.7Siemens15 Sept 2026

    Siemens Mendix SAML

    Critical Manufacturing; Information TechnologyCVE-2026-80465View CISA advisory
  16. MediumCVSS 6.1Siemens15 Sept 2026

    Siemens Teamcenter

    Critical Manufacturing; Information TechnologyCVE-2026-58113View CISA advisory
  17. HighCVSS 7.3Rockwell Automation3 Sept 2026

    Rockwell Automation ControlFLASH

    Critical Manufacturing; Energy; Water and Wastewater SystemsCVE-2026-12663View CISA advisory
  18. HighCVSS 7.5Rockwell Automation3 Sept 2026

    Rockwell Automation ArmorStart LT

    Critical ManufacturingCVE-2026-19471 +1View CISA advisory
  19. HighCVSS 7.5Rockwell Automation3 Sept 2026

    Rockwell Automation 1756-ENBT Module

    Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater SystemsCVE-2025-10478View CISA advisory
  20. HighCVSS 8.6Rockwell Automation1 Sept 2026

    Rockwell Automation RSLinx Classic

    Critical ManufacturingCVE-2026-9621 +3View CISA advisory
  21. HighCVSS 7.3Rockwell Automation1 Sept 2026

    Rockwell Automation Redundancy Module Configuration Tool

    Critical ManufacturingCVE-2026-9633 +1View CISA advisory
  22. HighCVSS 7.5Rockwell Automation1 Sept 2026

    Rockwell Automation Logix Platform

    Critical ManufacturingCVE-2026-9637View CISA advisory
  23. HighCVSS 7.8Rockwell Automation1 Sept 2026

    Rockwell Automation FactoryTalk Activation Manager

    Critical ManufacturingCVE-2026-16675View CISA advisory
  24. HighCVSS 7.5Rockwell Automation1 Sept 2026

    Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

    Critical ManufacturingCVE-2021-42260View CISA advisory
  25. HighCVSS 8.0Rockwell Automation1 Sept 2026

    Rockwell Automation Historian ME

    Chemical; Critical Manufacturing; Food and Agriculture; Healthcare and Public Health; Water and Wastewater SystemsCVE-2025-12768 +1View CISA advisory
  26. MediumCVSS 6.8Rockwell Automation27 Aug 2026

    Rockwell Automation OTTO Fleet Manager

    Critical Manufacturing; Transportation SystemsCVE-2026-75112View CISA advisory
  27. CriticalCVSS 10.0Siemens25 Aug 2026

    Siemens SIMATIC IoT2050 Advanced

    Chemical; Critical Manufacturing; Energy; Transportation SystemsCVE-2026-58115View CISA advisory
  28. HighCVSS 7.8Siemens18 Aug 2026

    Siemens Simcenter Nastran

    Critical Manufacturing; Defense Industrial Base; Energy; Healthcare and Public Health; Transportation SystemsCVE-2026-59086View CISA advisory
  29. HighCVSS 8.8Hitachi Energy13 Aug 2026

    Hitachi Energy APM Edge Product

    EnergyCVE-2026-43284 +1View CISA advisory
  30. HighCVSS 7.5Siemens13 Aug 2026

    Siemens License Server (SLS)

    Information TechnologyCVE-2026-69108 +1View CISA advisory

How we measure

We read the ICS Advisory Project database – an open, structured mirror of every CISA ICS-CERT advisory – and keep the vendors that matter to DACH industry.

Source: the ICS Advisory Project (github.com/icsadvprj, CC-licensed), which structures the advisories of the US agency CISA. CISA tracks globally; the advisories concern products used worldwide, including in Germany. No AI model, no keys.

All figures without guarantee. Data source: ICS Advisory Project (mirror of CISA ICS-CERT advisories, CC). The vendor selection is curated (industrial automation relevant to DACH) and not exhaustive. An advisory doesn't mean your plant is affected – check the respective original advisory. i6eal is not a security authority.

Frequently asked questions

What does the ICS/OT Vulnerability Index show?

How many new security advisories (ICS-CERT) exist for the automation vendors common in German factories – with severity, a vendor ranking, a monthly trend and the latest reports.

Where does the data come from?

From the ICS Advisory Project, an open structured database of all advisories from the US cybersecurity agency CISA (ICS-CERT). We filter to vendors relevant to DACH industry and refresh daily, as CISA publishes new advisories.

Does an advisory mean my plant is insecure?

Not necessarily. An advisory describes a reported flaw in a product. Whether your specific plant is affected depends on version, configuration and patch level – the original vendor/CISA advisory clarifies that.

Why does Siemens have so many advisories?

Large vendors with very broad, globally deployed portfolios (like Siemens) publish correspondingly more advisories. The absolute number is not a measure of “insecurity”.

Digitalisation that lasts.

Whether AI in production or connected OT: we bring new technology into operation securely.